<?xml version="1.0" encoding="utf-8"?>
			
			<rss version="2.0">
			<channel>
			<title>DickBlog - Not much original comment, but lots of great resources - Security/Viruses/Hoaxes and Scams</title>
			<link>http://www.dickblog.com/index.cfm</link>
			<description>DickBlog.com</description>
			<language>en-us</language>
			<pubDate>Thu, 09 Sep 2010 07:09:17 +0100</pubDate>
			<lastBuildDate>Mon, 05 Mar 2007 09:54:00 +0100</lastBuildDate>
			<generator>BlogCFC</generator>
			<docs>http://blogs.law.harvard.edu/tech/rss</docs>
			<managingEditor>dick@dickblog.com</managingEditor>
			<webMaster>dick@dickblog.com</webMaster>
			
			<item>
				<title>Self-signing your secure certificate - SSL for free</title>
				<link>http://www.dickblog.com/index.cfm/2007/3/5/Selfsigning-your-secure-certificate--SSL-for-free</link>
				<description>
				
				Here&apos;s &lt;a href=&quot;http://www.stillnetstudios.com/2007/02/11/self-signing-your-secure-certificate-ssl-for-free/&quot; target=&quot;_blank&quot;/&gt;how to do it&lt;/a&gt; or, for IIS6, you can get Microsoft to do the work with their SelfSSL tool from the &lt;a href=&quot;http://www.microsoft.com/downloads/details.aspx?FamilyID=56fc92ee-a71a-4c73-b628-ade629c89499&amp;DisplayLang=en&quot; target=&quot;_blank&quot;&gt;IIS Resource Kit&lt;/a&gt;. Barney has a posting on an &lt;a href=&quot;http://www.barneyb.com/barneyblog/2005/11/07/apachessl-on-osx/&quot; target=&quot;_blank&quot;&gt;issue with Apache and OSX&lt;/a&gt;. 
				</description>
				
				<category>Windows</category>				
				
				<category>Security/Viruses/Hoaxes and Scams</category>				
				
				<category>Apache</category>				
				
				<category>Mac OSX</category>				
				
				<pubDate>Mon, 05 Mar 2007 09:54:00 +0100</pubDate>
				<guid>http://www.dickblog.com/index.cfm/2007/3/5/Selfsigning-your-secure-certificate--SSL-for-free</guid>
				
			</item>
			
			<item>
				<title>OpenID</title>
				<link>http://www.dickblog.com/index.cfm/2007/3/5/OpenID</link>
				<description>
				
				&lt;a href=&quot;http://openid.net/&quot; target=&quot;_blank&quot;&gt;OpenID&lt;/a&gt; is an open, decentralized, free framework for user-centric digital identity.

Nice idea, now where can I use it...

Here&apos;s some more resources...

&lt;ul&gt;
&lt;li&gt;&lt;a href=&quot;http://simonwillison.net/2007/Feb/25/six/&quot; target=&quot;_blank&quot;&gt;http://simonwillison.net/2007/Feb/25/six/&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;http://pip.verisignlabs.com/&quot; target=&quot;_blank&quot;&gt;http://pip.verisignlabs.com/&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;http://www.indiankey.com/cfopenid/examples/login.cfm&quot; target=&quot;_blank&quot;&gt;http://www.indiankey.com/cfopenid/examples/login.cfm&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;http://openid.net/wiki/index.php/Public_OpenID_providers&quot; target=&quot;_blank&quot;&gt;http://openid.net/wiki/index.php/Public_OpenID_providers&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt; 
				</description>
				
				<category>Web Stuff</category>				
				
				<category>Security/Viruses/Hoaxes and Scams</category>				
				
				<pubDate>Mon, 05 Mar 2007 09:48:00 +0100</pubDate>
				<guid>http://www.dickblog.com/index.cfm/2007/3/5/OpenID</guid>
				
			</item>
			
			<item>
				<title>Windows Password Cracker</title>
				<link>http://www.dickblog.com/index.cfm/2007/2/9/Windows-Password-Cracker</link>
				<description>
				
				&lt;a href=&quot;http://ophcrack.sourceforge.net/&quot; target=&quot;_blank&quot;&gt;Ophcrack&lt;/a&gt; is a Windows password cracker based on rainbow tables. It is a very efficient implementation of rainbow tables done by the inventors of the method. It comes with a GTK+ Graphical User Interface and runs on Windows, Mac OS X (Intel CPU) as well as on Linux. 
				</description>
				
				<category>Windows</category>				
				
				<category>Security/Viruses/Hoaxes and Scams</category>				
				
				<pubDate>Fri, 09 Feb 2007 15:00:00 +0100</pubDate>
				<guid>http://www.dickblog.com/index.cfm/2007/2/9/Windows-Password-Cracker</guid>
				
			</item>
			
			<item>
				<title>SQL Injection Attacks by Example</title>
				<link>http://www.dickblog.com/index.cfm/2006/6/12/SQL-Injection-Attacks-by-Example</link>
				<description>
				
				If you have developed a web application with a database back-end, you should check out this article titled &lt;a href=&quot;http://www.unixwiz.net/techtips/sql-injection.html&quot; target=&quot;_blank&quot;&gt;SQL Injection Attacks by Example&lt;/a&gt;. It clearly explains what a SQL injection attack is and shows you how defend against such attacks. 
				</description>
				
				<category>Database</category>				
				
				<category>Security/Viruses/Hoaxes and Scams</category>				
				
				<pubDate>Mon, 12 Jun 2006 13:58:00 +0100</pubDate>
				<guid>http://www.dickblog.com/index.cfm/2006/6/12/SQL-Injection-Attacks-by-Example</guid>
				
			</item>
			
			<item>
				<title>Cross Site Scripting (XSS)</title>
				<link>http://www.dickblog.com/index.cfm/2006/4/26/Cross-Site-Scripting-XSS</link>
				<description>
				
				After a little investigation I think you shouldn&apos;t try to strip out any HTML from a users input, within reason, but to bracket the output of all their input with HTMLEditFormat(). That way any sillyness will be displayed in all it&apos;s glory!

This of course is in addition to adding &lt;cfset this.scriptProtect=&quot;true&quot;&gt; to your Application.cfc or the scriptprotect attribute of the cfapplication tag in CFMX 7. This is preferred over blindly checking the &quot;Enable Global Script Protection&quot; checkbox in the Administrator as it gives more flexibility.

See &lt;a href=&quot;http://www.petefreitag.com/item/362.cfm&quot; target=&quot;_blank&quot;&gt;Pete Freitag&apos;s blog&lt;/a&gt; for more info.

Also there&apos;s a good article on &lt;a href=&quot;http://cfdj.sys-con.com/read/41943.htm&quot; target=&quot;_blank&quot;&gt;SysCon&lt;/a&gt;.

Plus a good faq at &lt;a href=&quot;http://www.cgisecurity.com/articles/xss-faq.shtml&quot; target=&quot;_blank&quot;&gt;http://www.cgisecurity.com/articles/xss-faq.shtml&lt;/a&gt; 
				</description>
				
				<category>Security/Viruses/Hoaxes and Scams</category>				
				
				<category>ColdFusion MX 7</category>				
				
				<pubDate>Wed, 26 Apr 2006 10:32:00 +0100</pubDate>
				<guid>http://www.dickblog.com/index.cfm/2006/4/26/Cross-Site-Scripting-XSS</guid>
				
			</item>
			
			<item>
				<title>Security Presentation</title>
				<link>http://www.dickblog.com/index.cfm/2006/4/24/Security-Presentation</link>
				<description>
				
				Here&apos;s a great &lt;a href=&quot;http://video.google.com/videoplay?docid=5159636580663884360&quot;&gt;web security presentation&lt;/a&gt; by Mike Andrews. Jump to minutes 25, 40 and 55. 
				</description>
				
				<category>Security/Viruses/Hoaxes and Scams</category>				
				
				<pubDate>Mon, 24 Apr 2006 15:03:00 +0100</pubDate>
				<guid>http://www.dickblog.com/index.cfm/2006/4/24/Security-Presentation</guid>
				
			</item>
			
			<item>
				<title>Securing the Admin Directory</title>
				<link>http://www.dickblog.com/index.cfm?mode=entry&amp;entry=4EF04452-FB79-B685-833F98C57FBEDCBD</link>
				<description>
				
				Ray Camden has started some more &lt;a href=&quot;http://ray.camdenfamily.com/index.cfm/2005/7/22/How-NOT-To-Do-Directory-Security&quot; target=&quot;_blank&quot;&gt;security chatter&lt;/a&gt;!&lt;br/&gt; 
				</description>
				
				<category>Security/Viruses/Hoaxes and Scams</category>				
				
				<category>ColdFusion MX 7</category>				
				
				<pubDate>Mon, 25 Jul 2005 17:59:00 +0100</pubDate>
				<guid>http://www.dickblog.com/index.cfm?mode=entry&amp;entry=4EF04452-FB79-B685-833F98C57FBEDCBD</guid>
				
			</item>
			
			<item>
				<title>Secure Password</title>
				<link>http://www.dickblog.com/index.cfm?mode=entry&amp;entry=3979563C-FBD7-E3F9-6D06496C0071E5D0</link>
				<description>
				
				Is your password secure? &lt;a href=&quot;http://www.securitystats.com/tools/password.php&quot; target=&quot;_blank&quot;&gt;Check it out here&lt;/a&gt;!&lt;br/&gt; 
				</description>
				
				<category>Security/Viruses/Hoaxes and Scams</category>				
				
				<pubDate>Thu, 21 Jul 2005 13:57:00 +0100</pubDate>
				<guid>http://www.dickblog.com/index.cfm?mode=entry&amp;entry=3979563C-FBD7-E3F9-6D06496C0071E5D0</guid>
				
			</item>
			
			<item>
				<title>Google Hacking Database</title>
				<link>http://www.dickblog.com/index.cfm?mode=entry&amp;entry=1FC333DB-7E97-F825-569AB906FCDF4FD4</link>
				<description>
				
				Make sure you&apos;re not &lt;a href=&quot;http://johnny.ihackstuff.com/index.php?module=prodreviews&quot; target=&quot;_blank&quot;&gt;listed on this site of exposed websites&lt;/a&gt; found by a Google hack.&lt;br/&gt; 
				</description>
				
				<category>Security/Viruses/Hoaxes and Scams</category>				
				
				<pubDate>Thu, 17 Feb 2005 09:59:00 +0100</pubDate>
				<guid>http://www.dickblog.com/index.cfm?mode=entry&amp;entry=1FC333DB-7E97-F825-569AB906FCDF4FD4</guid>
				
			</item>
			
			<item>
				<title>Windows Security Tools</title>
				<link>http://www.dickblog.com/index.cfm?mode=entry&amp;entry=AE8FBF80-7E97-F825-5AFD41F19F34BAC1</link>
				<description>
				
				&lt;h3 id=&quot;post-90&quot; class=&quot;storytitle&quot;&gt;&lt;a title=&quot;Permanent Link: Windows Security Tools&quot; rel=&quot;bookmark&quot; href=&quot;http://www.webmilhouse.com/wordpress/index.php?p=90&quot;&gt;Windows Security Tools&lt;/a&gt;&lt;/h3&gt; 
				</description>
				
				<category>Windows</category>				
				
				<category>Security/Viruses/Hoaxes and Scams</category>				
				
				<pubDate>Wed, 26 Jan 2005 10:27:00 +0100</pubDate>
				<guid>http://www.dickblog.com/index.cfm?mode=entry&amp;entry=AE8FBF80-7E97-F825-5AFD41F19F34BAC1</guid>
				
			</item>
			
			<item>
				<title>Preventing Comment Spam</title>
				<link>http://www.dickblog.com/index.cfm?mode=entry&amp;entry=8A45EDA7-7E97-F825-5F42FD7AA847E49D</link>
				<description>
				
				Google and others have got together to screen out spam in blog comments by adding the rel=&amp;quot;nofollow&amp;quot; attribute. See here...&lt;br/&gt;&lt;br/&gt;&lt;a href=&quot;http://www.google.com/googleblog/2005/01/preventing-comment-spam.html&quot; target=&quot;_blank&quot;&gt;http://www.google.com/googleblog/2005/01/preventing-comment-spam.html&lt;/a&gt;&lt;br/&gt; 
				</description>
				
				<category>Security/Viruses/Hoaxes and Scams</category>				
				
				<pubDate>Wed, 19 Jan 2005 09:18:00 +0100</pubDate>
				<guid>http://www.dickblog.com/index.cfm?mode=entry&amp;entry=8A45EDA7-7E97-F825-5F42FD7AA847E49D</guid>
				
			</item>
			
			<item>
				<title>Common Security Vulnerabilities in e-Commerce Systems</title>
				<link>http://www.dickblog.com/index.cfm?mode=entry&amp;entry=76212658-805F-FD36-6C84150256D163C9</link>
				<description>
				
				&lt;P&gt;&lt;A class=&quot;&quot; href=&quot;http://www.securityfocus.com/infocus/1775&quot; target=_blank&gt;SecurityFocus&lt;/A&gt; has a good article on the most common forms of security vulnerabilities for e-commerce systems, but I think that a lot of web apps may be vulnerable to some of these as well (think sql injection, session hijacking, and so forth).&lt;/P&gt; 
				</description>
				
				<category>Security/Viruses/Hoaxes and Scams</category>				
				
				<pubDate>Thu, 07 Oct 2004 00:00:00 +0100</pubDate>
				<guid>http://www.dickblog.com/index.cfm?mode=entry&amp;entry=76212658-805F-FD36-6C84150256D163C9</guid>
				
			</item>
			
			<item>
				<title>The forecast of results of matches on Euro-2004</title>
				<link>http://www.dickblog.com/index.cfm?mode=entry&amp;entry=76211590-805F-FD36-6CA83563C2BEF1D0</link>
				<description>
				
				&lt;P&gt;I certainly seem to attract some weird get-rich-quick scams!&lt;/P&gt;
&lt;P&gt;===============================================&lt;/P&gt;
&lt;P&gt;In January, 2001 the group of the Russian mathematicians had been started work on gathering statistical given European soccer teams. The huge database of all official and companionable matches between the European teams has been created. For 3 years of work the empirical law, which allows define result of a match between soccer teams from Europe, with probability of 95 % has been found. The given law takes into account place of carrying out of a match and set of other factors, which influence result of a match. I took part in this project. The received results have proved to be true in practice. Now I have an opportunity to send you the forecast for any five matches of the championship of Europe 2004 in Portugal. You can make rates on a tote and receive compensation. The forecast for three matches costs 300 euros. To receive the forecast to you it is necessary to transfer 300 euros to the account web money WMExxxxxxx and to write the letter on the electronic address &lt;A href=&quot;mailto:xxxxxxxxxxxx@yahoo.com&quot;&gt;xxxxxxxxxxxx@yahoo.com&lt;/A&gt; in which you specify matches interesting you. The answer will be sent on your return address. You can familiarize with system web money on &lt;A class=&quot;&quot; href=&quot;http://www.wmtransfer.com/&quot; target=_blank&gt;http://www.wmtransfer.com/&lt;/A&gt;. &lt;/P&gt;
&lt;P&gt;I wish you success on Euro-2004. &lt;/P&gt;
&lt;P&gt;===============================================&lt;/P&gt;
&lt;P&gt;Links and email addresses changed to protect the guilty.&lt;/P&gt; 
				</description>
				
				<category>Security/Viruses/Hoaxes and Scams</category>				
				
				<pubDate>Mon, 10 May 2004 00:00:00 +0100</pubDate>
				<guid>http://www.dickblog.com/index.cfm?mode=entry&amp;entry=76211590-805F-FD36-6CA83563C2BEF1D0</guid>
				
			</item>
			
			<item>
				<title>Another PayPal Scam</title>
				<link>http://www.dickblog.com/index.cfm?mode=entry&amp;entry=76211428-805F-FD36-6CB878519659F615</link>
				<description>
				
				&lt;P&gt;Got the following&amp;nbsp;email today&lt;/P&gt;
&lt;P&gt;This is the first time I&apos;ve had this one. I like the ColdFusion quote. That got me interested for a while! After having a quick Google I&apos;ve found that&amp;nbsp;this scam seems quite popular, but with different companies named, like:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Carex Pharmaceuticals Corporation &lt;/LI&gt;
&lt;LI&gt;Insta-Pro&amp;nbsp;International&amp;nbsp;Corporation&lt;/LI&gt;&lt;/UL&gt;
&lt;P&gt;===============================================&lt;/P&gt;
&lt;P&gt;From: &quot;Leonard&quot;&lt;BR&gt;Date: Mon, 26 Apr 2004 00:16:48 +0000 &lt;BR&gt;To: &quot;Billy&quot; &lt;BR&gt;Subject: Have a Paypal Account? Want to Make SERIOUS Money With It? &lt;/P&gt;
&lt;P&gt;Dear Sir or Madam, &lt;/P&gt;
&lt;P&gt;Do you have a Paypal account and want to earn a SIGNIFICANT amount of money by doing practically NOTHING? If you do, then this is your opportunity to start a business relationship with an international graphics supply company &quot;Mentor Graphics Corporation&quot;. Mentor Graphics Corporation is NOT a marketing company; there is NOTHING to buy and NOTHING to sign up for, and most importantly, NO WORK is required on your part in order to collect large quantities of cash within a 1-24 hours of receiving this message. Our company located in Europe (United Kingdom). We have many clients who work with us and buy our products. We need YOU because we have many branches in USA and Europe. Right now we need people who have verified PayPal accounts. &lt;/P&gt;
&lt;P&gt;Our company gives you first time an opportunity to earn 20 % from all translations that will go trough your account in paypal. After next transactions you will receive 25% as a Gold member. After receiving money on your PayPal account, you will have to send 80% to our manager to Europe through Western Union. &lt;/P&gt;
&lt;P&gt;Here are the requirements: &lt;/P&gt;
&lt;P&gt;1. You must have verified PayPal account. &lt;BR&gt;2. You have to tell us your full name, real telephone number, your e-mail registered in PayPal and when you&apos;re ready to work with our company just send an e-mail to &quot;[DickBlog: address removed]&quot;&lt;/P&gt;
&lt;P&gt;This is your chance to try yourself in your new money making program. You will see the result in 24 hours after sending your information to our email &quot;[DickBlog: address removed]&quot; &lt;/P&gt;
&lt;P&gt;AAout Mentor Graphics. &lt;/P&gt;
&lt;P&gt;Mentor Graphics Corporation is a world leader in electronic hardware and software design solutions, providing products, consulting services and award-winning support for the world&apos;s most successful electronics and semiconductor companies. Established in 1981, Mentor Graphics reported revenues over the last 12 months of more than $600 million and employs approximately 3,100 people worldwide. Mentor Graphics Corporation offers a variety of services when it comes to website design. Our highly experienced staff can create anything from a simple website used for advertising to a highly technical website with a store or catalog to be updated regularly, or even your own chat room. We are especially strong in database interfacing using Cold Fusion and iHTML. &lt;/P&gt;
&lt;P&gt;Roger Arpino &lt;BR&gt;Mentor Graphics Corporation, &lt;BR&gt;Executive Officer&lt;/P&gt;
&lt;P&gt;===============================================&lt;/P&gt; 
				</description>
				
				<category>Security/Viruses/Hoaxes and Scams</category>				
				
				<pubDate>Mon, 26 Apr 2004 00:00:00 +0100</pubDate>
				<guid>http://www.dickblog.com/index.cfm?mode=entry&amp;entry=76211428-805F-FD36-6CB878519659F615</guid>
				
			</item>
			
			<item>
				<title>Open Web Application Security Project (OWASP)</title>
				<link>http://www.dickblog.com/index.cfm?mode=entry&amp;entry=762113D8-805F-FD36-6C52D0FFC586C637</link>
				<description>
				
				&lt;P&gt;&quot;&lt;A class=&quot;&quot; href=&quot;http://www.owasp.org/&quot; target=_blank&gt;OWASP&lt;/A&gt; was started in September 2000 with its mission to create an open source community where people could advance their knowledge about web application and web services security issues by either contributing their knowledge to the education of others or by learning about the topic from documentation and software produced by the project.&quot;&lt;/P&gt;
&lt;P&gt;Lots of useful stuff here. Especially their &lt;A class=&quot;&quot; href=&quot;http://www.owasp.org/documentation/guide/&quot; target=_blank&gt;guide&lt;/A&gt;. Worth reading and keeping in contact with.&lt;/P&gt;
&lt;P&gt;There is a online version of the document. I think the choice chapters are:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A class=&quot;&quot; href=&quot;http://www.cgisecurity.com/owasp/html/ch2.html&quot; target=_blank&gt;Chapter 2. Overview&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A class=&quot;&quot; href=&quot;http://www.cgisecurity.com/owasp/html/ch6.html&quot; target=_blank&gt;Chapter&amp;nbsp;6.&amp;nbsp;Authentication&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A class=&quot;&quot; href=&quot;http://www.cgisecurity.com/owasp/html/ch7.html&quot; target=_blank&gt;Chapter&amp;nbsp;7.&amp;nbsp;Managing User Sessions&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A class=&quot;&quot; href=&quot;http://www.cgisecurity.com/owasp/html/ch9.html&quot; target=_blank&gt;Chapter&amp;nbsp;9.&amp;nbsp; Event Logging&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A class=&quot;&quot; href=&quot;http://www.cgisecurity.com/owasp/html/ch10.html&quot; target=_blank&gt;Chapter&amp;nbsp;10.&amp;nbsp; Data Validation&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A class=&quot;&quot; href=&quot;http://www.cgisecurity.com/owasp/html/ch11.html&quot; target=_blank&gt;Chapter&amp;nbsp;11.&amp;nbsp; Preventing Common Problems&lt;/A&gt;&lt;/LI&gt;&lt;/UL&gt; 
				</description>
				
				<category>Security/Viruses/Hoaxes and Scams</category>				
				
				<pubDate>Fri, 23 Apr 2004 00:00:00 +0100</pubDate>
				<guid>http://www.dickblog.com/index.cfm?mode=entry&amp;entry=762113D8-805F-FD36-6C52D0FFC586C637</guid>
				
			</item>
			</channel></rss>